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1. Computing device with user interface comprising 
means for implementing a series of applications, these means 
including in particular a first virtual machine /functioning 
profile execution space (100, Pi, 200, P2) and a second 
virtual machine/ fvmctioning profile execution space (100, PI, 
200, P2) , wherein the two execution spaces are hosted by one 
same physical processing means (400) which is arranged so that 
it cannot be separated into two parts without destroying this 
physical processing means (400) , each execution space hosting 
applications (110, 120, 130, 140, 220, 230), the applications 
of the second execution space (100, PI, 200, P2) being 
applications with a specifically higher level of security than 
the applications of the first execution space (100, PI, 200, 
P2) since the applications (110, 120, 130, 210, 220, 230) of 
the first execution space (100, PI, 200, P2) are applications 
which can be modified by the user, whilst the applications 
(110, 120, 130, 210, 220, 230) of the second execution space 
(100, PI, 200, P2) are applications which cannot be modified 

characterized in that, wherein the second 
(100, PI, 200, P2) differs from the first 
(100, PI, 200, P2) by at least its virtual 



by the user, 
execut i on space 
execution space 



machine (100, 200) . 

2. Device as in claim 1, characterized in that the 
applications (110, 120, 130, 210, 220, 230) of the second 
execution space (100. PI, 200, P2) are applications which can 
be modified by a security operator belonging to the group 
consisting of telephony operators, banks, providers of 
multimedia items with selective or paying distribution, 
service providers operating against electronic signature via 
said device. 
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3. Device as in claim 1 or claim 2, characterized in 
that it forms a telephone terminal. 

5 4. Device as in claim 3, characterized in that it forms 

a mobile telephony terminal. 

5. Device as in any of the preceding claims, 
characterized in that it comprises communication means (13 0, 

10 230, 300) between the two execution spaces (100, PI, 200, P2) . 

6. Device as in claim 5, characterized in that the 
communication means (130, 230, 300) between the two execution 
spaces are designed to authorize an application (130, 230) of 

15 one of the two execution spaces to have recourse to processing 
means of the second execution space (100, Pi, 20 0, P2) . 

7. Device as in any of the preceding claims, 
characterized in that each of the two execution spaces 

20 includes at least one separate API (120, 130, 220, 230) . 

8. Device as in any of the preceding claims, 
characterized in that the communication means include an API 
"stub" (130, 230) whose role is to have recourse to resources 

25 of the opposite execution space (100, PI, 200, P2) , these 
resources implementing a selection regarding access to them in 
relation to the caller application (110, 210). 

9. Device as in any of the preceding claims, 
3 0 characterized in that the communication means between the two 

execution spaces (100, PI, 2 00, P2) include means implementing 
serialization/deserialization or marshal 1 ing/unmarshal 1 ing . 
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10. Device as in any of the preceding claims, 
characterized in that one of the two execution spaces (100, 
PI, 200, P2) includes a profile of STIP type. 

5 11. Device as in any of the preceding claims, 

characterized in that one of the two execution spaces (100, 
PI, 2 00, P2) includes a MIDP profile. 

12. Device as in any of the preceding claims, 
10 characterized in that the profiles (P1,P2) of each of the two 
execution spaces (100, PI, 200, P2) are respectively a STIP 
profile and a profile forming part of the group consisting of 
STIP, MIDP, OSGI and ".net" profiles. 
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